Whonix live mode / amnesia / amnesic / non-persistent / anti-forensics

Added to Combine Kicksecure ™ Live VMs with Read-only Mode for Virtual Hard Drives chapter VirtualBox in Kicksecure wiki just now:

On Debian bookworm based Kicksecure ™ 17 (and above) / Newer VirtualBox versions:

  • VirtualBox might no longer support VBoxInternal/Devices/lsilogicsas/0/LUN#0/AttachedDriver/Config/ReadOnly. Settings set thorugh VBoxManage setextradata are not officially supported and might be gone at some time such as now.
  • VirtualBox documentation chapter Special Image Write Modesarchive.org mentions immutable images but this might not be as good as read-only images.

Above two issues are not easy to fix.

Help welcome!

Link to source code:

rootovl vs overlayfs discussed here:
Boot Existing, Usual Linux Installation from Hard Disk in Live Mode / read-only mode with dracut · Issue #1565 · dracutdevs/dracut · GitHub

https://www.reddit.com/r/Whonix/comments/15q7vcs/have_the_dev_team_tested_the_antiforensic/

1 Like

issue with older build versions still using initramfs-tools and fix:

Merged.